I cannot locate the OCC's March 2024 Third-Party Risk Management Bulletin in the supplied sources. The sources provided cover NIST's Cybersecurity Framework, NIST's Privacy Framework, and FTC privacy and security guidance, but none contain the specific OCC bulletin referenced in the brief.
Without access to the actual bulletin, I cannot describe its requirements, effective dates, scope, due diligence expectations, contract provisions, monitoring obligations, customer complaint procedures, or documentation standards. Any attempt to do so would require inventing content not present in the sources.
What This Means for Bank Leadership
Regulatory bulletins on third-party risk management typically create a governance problem: board members and chief executives are accountable for compliance outcomes, but the technical details span multiple departments. Risk committees own policy. Compliance teams interpret requirements. Technology groups implement controls. Legal reviews contracts. Each group holds part of the picture, but no single executive owns the integrated risk decision.
This structure makes it difficult to answer basic questions: Are we compliant today? What evidence would an examiner expect? Which fintech relationships carry unacceptable risk? Who decides when to exit a partnership? Without executive-level ownership of the cybersecurity and technology risk dimension, institutions often discover gaps only when examiners arrive.
The Role of Virtual CISO Leadership in Third-Party Risk Programs
A [virtual CISO provides executive governance](/vciso/) that closes this ownership gap. The vCISO translates regulatory expectations into risk decisions, establishes the governance structure that determines what is acceptable, and provides the board and executive leadership with a clear position on compliance status. This is not project management or technical implementation; it is strategic accountability for the institution's technology risk posture across third-party relationships.
For fintech partnerships specifically, the vCISO determines what due diligence is sufficient before a relationship begins, what contract provisions protect the institution's interests, how monitoring will detect problems before they become compliance issues, and what evidence will satisfy examiners. The vCISO also decides when a partnership must be restructured or terminated based on risk that the institution cannot accept.
Who Owns What in Third-Party Risk Governance
Effective third-party risk management requires clarity about decision rights:
- The board sets risk appetite and holds executive management accountable for compliance with regulatory expectations.
- The chief executive or chief risk officer owns the institution's overall third-party risk program, including the decision to enter or exit partnerships.
- The virtual CISO owns the cybersecurity and technology risk dimension: determining what controls are adequate, what monitoring is required, and what constitutes unacceptable risk in technology relationships.
- Compliance interprets regulatory requirements and validates that the institution's practices satisfy examiner expectations.
- Legal reviews contract language and ensures the institution's rights are protected.
- Internal audit provides independent assurance that the program operates as designed.
Without a clear owner of the cybersecurity risk decision, institutions often implement activity without achieving the outcome regulators expect: vendors complete questionnaires that no one with technical judgment reviews, monitoring produces reports that no executive interprets, and contract provisions exist but do not actually transfer risk.
How This Relates to Broader Vendor and MSP Oversight
Fintech partnerships are one category within the institution's broader third-party risk universe. Banks typically maintain relationships with core banking system providers, cloud infrastructure vendors, managed security service providers, payment processors, and dozens of other technology suppliers. Each relationship carries cybersecurity risk; some also involve regulatory obligations that extend to the vendor's practices.
The governance structure that supports regulatory compliance for fintech partnerships should integrate with the institution's overall vendor risk management program. The same executive who determines acceptable cybersecurity risk in a fintech relationship should make comparable risk decisions for cloud providers, MSPs, and other critical vendors. Fragmented oversight—where different departments manage different vendor categories using different standards—creates compliance gaps and makes it impossible to give the board a coherent view of third-party risk.
Managed service providers play a distinct operational role. An MSP implements technical controls, manages infrastructure, and responds to incidents. The vCISO provides strategic governance: deciding what controls are required, determining whether the MSP's work satisfies regulatory expectations, and advising leadership when third-party risk exceeds acceptable levels. Both functions are necessary; neither replaces the other.
What Leadership Should Do Next
If your institution partners with fintech companies or other technology providers subject to regulatory oversight, start by confirming who owns the cybersecurity risk decision. Not who executes vendor reviews or maintains the vendor list—who is accountable to the board and to regulators for determining that third-party technology risk is acceptable.
If that accountability is unclear or distributed across multiple departments, you have a governance gap. The next step is establishing executive ownership of the technology risk dimension within your third-party risk program. For many institutions, a [virtual CISO engagement](/vciso/) provides that ownership without the overhead of a full-time executive hire.
Once ownership is clear, validate that your current fintech partnerships meet regulatory expectations: due diligence that reflects actual technology risk, contracts that give you enforceable rights, monitoring that detects problems before they become compliance issues, and documentation that will satisfy examiners. If you cannot produce that evidence today, you have implementation gaps that require immediate attention.
Finally, integrate fintech oversight with your broader third-party risk program. The same governance structure, risk appetite, and decision-making authority should apply across all regulated technology relationships.
When to Seek External Leadership
If your institution lacks a clear executive owner for cybersecurity risk in third-party relationships—or if your current structure produces activity but not regulatory confidence—a confidential consultation can clarify your options. Heights Consulting Group provides virtual CISO leadership that establishes governance, interprets regulatory expectations, and gives your board defensible answers about third-party technology risk.
This is not a compliance project. It is executive accountability for a risk outcome that regulators expect someone to own. If you need that ownership, let's talk.
Sources
- Cybersecurity Framework | NIST , www.nist.gov
- Privacy and Security | Federal Trade Commission , www.ftc.gov
- Privacy Framework | NIST , www.nist.gov
Related service: Vendor, MSP and Third-Party Oversight
Clear accountability for the security work your providers perform: defined expectations, stated evidence requirements, and a review process that holds over the life of the contract.